Skip to main content
Home/Blog/X €120 Million DSA Fine 2026: Ad Repository Transparency Failures and Advertiser Implications
Back to Intelligence Hub
regulationEuropean UnionRisk Level: critical

X €120 Million DSA Fine 2026: Ad Repository Transparency Failures and Advertiser Implications

The EU's first DSA non-compliance fine hit X for an ad repository that obscured who paid for ads. Here is what the €120M decision changes for advertisers buying X inventory.

May 18, 202616 min readAuditSocials Research
TweetShare
Quick Answer

On 5 December 2025 the European Commission issued a €120 million fine against X, the first non-compliance decision under the Digital Services Act (DSA), and it targeted transparency infrastructure rather than any single ad. The decision identified three breach categories: deceptive verification design (paid "verified" status granted without meaningful identity checks), an ad repository deficiency (missing advertiser identity, ad content and topic, poor searchability, and processing delays), and a researcher-data-access failure (terms and procedural barriers blocking vetted researchers). The fine amount was calculated on the nature and gravity of the infringements, the number of affected EU users, and the duration of the conduct. For advertisers, the practical effect is that assumptions must be internalized: the public ad repository can no longer be treated as the authoritative record of what you ran, the verified badge is no longer an identity or trust signal, and reduced external research visibility shifts adjacency monitoring back to first-party brand-safety controls. The decision does not ban advertising on X; it is a control-design trigger. The single highest-leverage action is maintaining an independent system of record for every campaign. Track remediation on the Policy Change Tracker, map disclosure and record-keeping obligations with the Legal Compliance Scan, and align platform rules with the X ads policy guide.

X €120 Million DSA Fine 2026: Ad Repository Transparency Failures and Advertiser Implications

The First DSA Non-Compliance Fine

On 5 December 2025 the European Commission issued a €120 million fine against X — the first non-compliance decision under the Digital Services Act (DSA). This matters to advertisers far beyond X itself, because the Commission did not penalize a single piece of content. It penalized the transparency infrastructure around advertising and platform identity: the ad repository, the paid verification system, and the researcher data access regime.

For media buyers, the lesson is structural. The DSA's enforcement priority is not the individual ad creative but whether the platform can show, in a usable public archive, who paid for an ad, what the ad said, and who it targeted. When that archive is deficient, every advertiser running inventory on the platform inherits a transparency exposure they did not create and cannot fix from the ad account.

EU regulators have publicly criticized X's ad repository, indicating it lacked key information such as ad content and the paying entity and that design features and access barriers undermined its purpose — consistent with the Commission's December 2025 DSA findings against X.

This guide breaks down what the decision actually found, why the ad repository failure is the advertiser's problem and not only the platform's, and the concrete steps to take before continuing to buy X inventory in 2026.

What the December 2025 Decision Found

The Commission's decision identified three distinct breach categories. Each maps to a different DSA transparency obligation, and each carries a different implication for advertisers. The table summarizes the findings as published.

Breach categoryWhat the Commission foundAdvertiser implication
Deceptive verification designPaid "verified" status granted without meaningful identity verificationVerified accounts are not a reliable trust or brand-safety signal
Ad repository deficiencyMissing advertiser identity, ad content and topic; poor searchability; processing delaysYour own ads may be inadequately documented in the public archive
Researcher data access failureTerms of service and procedural barriers blocked vetted researcher accessSystemic-risk visibility into adjacency and amplification is reduced

The fine amount was calculated on the nature and gravity of the infringements, the number of affected EU users, and the duration of the conduct. The Commission framed the ad repository deficiency as undermining the ability of the public, regulators, and researchers to scrutinize advertising — which is precisely the function advertisers depend on to demonstrate their own compliance. Track subsequent enforcement and remediation milestones through the policy tracker and review the broader framework in the EU DSA compliance overview.

Why the Ad Repository Failure Matters to Advertisers

Under the DSA, every Very Large Online Platform must maintain a public ad repository containing, for each ad, the content of the advertisement, the natural or legal person on whose behalf it was presented, who paid for it, the period of display, the targeting parameters used, and the total reach. This is not a courtesy archive — it is the evidentiary backbone that lets a regulator, a journalist, or a competitor reconstruct exactly what an advertiser ran and to whom.

The Commission found X's repository missing the advertiser legal entity, the ad content and topic, and adequate searchability, with processing delays that frustrated access. For an advertiser, this produces a counterintuitive exposure: a deficient repository is not a benefit. If your campaign is later questioned — by a regulator, an NGO, or in litigation — the platform-side archive is the primary record of what you ran. A repository that is incomplete or unsearchable does not protect the advertiser; it removes the advertiser's ability to point to an authoritative, contemporaneous record of compliant disclosure and targeting.

  • Maintain an independent ad archive: retain creative, targeting parameters, payer entity, flight dates, and approvals for every X campaign — do not rely on the platform repository as your system of record.
  • Verify payer attribution: confirm the legal entity shown as the payer in any available repository entry matches the entity that should appear, especially where agencies or resellers are intermediaries.
  • Document political and issue ads separately: these carry heightened DSA transparency obligations and are the highest-scrutiny category in a deficient-repository environment.

Map the disclosure and record-keeping obligations across jurisdictions with the legal compliance scan, and pre-check campaign copy and claims with the AI compliance audit before spend so the independent archive contains compliant assets.

Deceptive Verification and Brand-Safety Exposure

The Commission's finding that paid verification is granted "without the company meaningfully verifying who is behind the account" has a direct brand-safety consequence. A large share of media-buying brand-safety and influencer-vetting workflows historically treated a verification badge as a lightweight authenticity proxy. The decision formally invalidates that assumption on this platform: a verified badge does not establish that the account is who it claims to be.

This changes two operational practices. First, influencer and partnership vetting on X cannot rely on the badge as an identity signal — independent verification of the entity, ownership, and history is required before a paid relationship. Second, adjacency risk increases: impersonation and inauthentic accounts that carry a paid badge can sit next to brand inventory while presenting a false credibility cue to the same audience seeing the ad. Treat the badge as a paid feature, not an identity attestation, and document the independent verification performed for any creator or partner relationship.

"Verification on a platform is a trust signal only to the extent the platform actually verifies identity. Where it does not, advertisers must replace the badge with their own due-diligence record — the badge is now a liability shortcut, not evidence.
— AuditSocials Research"

For creator partnerships, run disclosure and relationship documentation through the disclosure checker and align platform-specific rules with the X ads policy guide.

Researcher Data Access and Systemic-Risk Visibility

The third breach — blocking vetted researcher access through terms of service and procedural barriers — looks remote from media buying but is not. Researcher access under the DSA is the mechanism by which systemic risks such as coordinated inauthentic behavior, illegal-content amplification, and ad-adjacency to harmful material are independently measured. When that access is obstructed, advertisers lose an external check on the environment their ads run in.

In practical terms, a brand cannot outsource its adjacency monitoring to "the research community will catch it." With independent visibility reduced, the burden shifts back to the advertiser's own brand-safety tooling, inclusion and exclusion lists, and post-campaign placement audits. The defensible posture is to assume less external transparency, not more, and to compensate with stricter first-party controls and continuous monitoring rather than periodic spot checks.

  • Tighten inventory controls: prefer inclusion lists and topic exclusions over broad reach when external transparency is constrained.
  • Increase placement-audit cadence: move from quarterly to continuous adjacency review for sensitive categories.
  • Escalate political and crisis periods: apply heightened controls during elections and high-risk news cycles where amplification risk peaks.

Advertiser Playbook for X Inventory in 2026

The decision does not require advertisers to leave X. It requires them to stop treating the platform's transparency infrastructure as a substitute for their own. The playbook below is the defensible operating posture for buying X inventory while the remediation obligations are outstanding.

  • Own the system of record: maintain a complete, independent archive of every X campaign — creative, payer entity, targeting, flight dates, approvals — regardless of repository state.
  • Re-baseline verification: remove the verified badge from vetting criteria; require independent identity and ownership checks for creators and partners.
  • Strengthen adjacency controls: shift to inclusion-led buying and continuous placement audits given reduced external research visibility.
  • Escalate political/issue ads: apply the heightened-disclosure track and document targeting and payer attribution explicitly.
  • Monitor remediation status: the Commission's decision triggers an action-plan and remediation process — track milestones and reassess inventory posture as they resolve through the policy tracker.
  • Pre-flight every flight: validate copy, claims, and disclosures with the AI compliance audit so archived assets are defensible on their own.

The asymmetry is the same one that governs all transparency compliance: maintaining an independent record costs operational hours, while being unable to evidence what you ran on a platform whose own archive a regulator has formally found inadequate is an open-ended exposure.

X Advertiser Compliance Checklist

  • [ ] Independent archive maintained for every X campaign (creative, payer, targeting, dates, approvals)
  • [ ] Payer legal entity verified against intended entity, including agency/reseller chains
  • [ ] Verified badge removed from creator/partner vetting criteria
  • [ ] Independent identity and ownership checks documented for all paid relationships
  • [ ] Inclusion-led buying and continuous adjacency audits in place
  • [ ] Political/issue ads on heightened-disclosure track with targeting documented
  • [ ] Remediation milestones monitored and inventory posture reassessed on changes
  • [ ] Every flight pre-flighted for copy, claims, and disclosure compliance

Frequently Asked Questions

Does the €120M X fine mean advertisers should stop buying X inventory?
No, the December 2025 decision does not prohibit advertising on X and does not, by itself, make buying X inventory non-compliant for an advertiser. What it does is remove a set of assumptions that media buyers historically relied on, and the correct response is to replace those assumptions with first-party controls rather than to exit the platform reflexively. The Commission fined X for the state of its transparency infrastructure — a deficient ad repository, paid verification granted without meaningful identity checks, and obstructed researcher data access — not for the existence of advertising on the platform or for any particular advertiser's campaign. The practical consequence for an advertiser is that three things that were previously treated as the platform's responsibility now have to be internalized. First, the public ad repository can no longer be relied on as the authoritative record of what you ran, so the advertiser must maintain its own complete archive of creative, payer entity, targeting parameters, flight dates, and approvals for every campaign. Second, the verified badge is no longer an identity or trust signal, so creator and partner vetting must use independent verification. Third, with reduced external research visibility into systemic risks, adjacency monitoring shifts back to the advertiser's own brand-safety tooling and audit cadence. An advertiser that makes these three adjustments can continue to buy X inventory with a defensible posture; an advertiser that continues to lean on the platform's transparency infrastructure inherits an exposure the Commission has formally documented. The decision should therefore be read as a control-design trigger, not a platform ban. Track remediation milestones through the policy tracker and align platform-specific rules with the X ads policy guide so the posture is reassessed as the situation evolves rather than fixed at the moment of the fine.
Why is a deficient ad repository the advertiser's problem and not only the platform's?
It is intuitive to assume that a weak public ad archive is convenient for advertisers because less of what they ran is visible, but the opposite is true under the DSA enforcement logic, and understanding why is central to the defensible posture. The DSA requires every Very Large Online Platform to maintain a public repository that, for each advertisement, records the ad content, the entity on whose behalf it ran, who paid for it, the display period, the targeting parameters, and the total reach. This repository is the evidentiary backbone of advertising transparency: it is the contemporaneous, authoritative record a regulator, journalist, NGO, or court would consult to reconstruct exactly what an advertiser did. When the Commission finds that repository missing the advertiser legal entity, the ad content and topic, and adequate searchability, the advertiser loses the ability to point to an official, complete, time-stamped record demonstrating that its disclosures and targeting were compliant. If a campaign is later questioned, the absence of a reliable platform archive does not create deniability — it removes the advertiser's strongest exculpatory evidence and leaves only whatever the advertiser itself retained. This is why the correct response is to maintain an independent system of record that captures creative, payer attribution, targeting, flight dates, and approvals for every X campaign, treating the platform repository as unreliable until remediated. It is also why payer attribution deserves specific attention: where agencies or resellers sit between the brand and the platform, the legal entity recorded as payer can diverge from the entity that should appear, and a deficient repository makes that divergence harder to detect and correct. The political and issue-ad category warrants separate documentation because it carries heightened DSA transparency obligations and is the first place scrutiny lands when a repository is found inadequate. Map the cross-jurisdictional disclosure and record-keeping requirements with the legal compliance scan and validate that the assets entering your independent archive are compliant using the AI compliance audit before each flight.
How should brand-safety and influencer vetting change now that paid verification is not an identity signal?
The Commission's finding that X grants paid 'verified' status without meaningfully verifying who is behind an account formally invalidates a shortcut that was embedded in many brand-safety and influencer-vetting workflows: treating a verification badge as a lightweight authenticity proxy. Once a platform's badge is, as a matter of regulatory finding, decoupled from identity verification, any process that uses the badge as evidence of who an account is must be redesigned, because the badge now communicates only that someone paid for it. The first operational change is in influencer and partnership vetting. Before entering a paid relationship with a creator on X, the advertiser must independently verify the entity, its ownership, and its history rather than inferring legitimacy from the badge — this means corroborating identity through off-platform evidence, contractual representations, and documented due diligence that is retained as part of the campaign record. The second change is in adjacency and impersonation risk management. Because impersonation and inauthentic accounts can carry a paid badge, brand inventory can appear next to accounts that present a false credibility cue to the very audience seeing the ad, which increases both reputational and amplification risk. The mitigation is to strengthen inclusion lists, tighten topic and account exclusions, and increase the cadence of placement audits rather than relying on badge-based filtering. The third change is documentary: every creator or partner relationship should now carry an explicit due-diligence file showing the independent verification performed, so that if the relationship is later questioned the advertiser can demonstrate it did not rely on the invalidated signal. In short, the badge moves from being a vetting input to being irrelevant to vetting, and the verification work it implicitly performed must be done explicitly and recorded. Run relationship and disclosure documentation through the disclosure checker and align the rest of the workflow with the X ads policy guide so the vetting standard is consistent across every paid relationship on the platform.
What does the researcher-data-access breach have to do with media buying?
The third breach in the decision — X obstructing vetted researcher access through its terms of service and procedural barriers — appears to be an academic-freedom issue rather than a media-buying concern, but it has a concrete operational consequence for advertisers that is easy to miss. Under the DSA, vetted researcher access is the primary external mechanism for independently measuring systemic risks on a platform: coordinated inauthentic behavior, amplification of illegal or harmful content, and the adjacency of advertising to that content. Advertisers, often without articulating it, have benefited from this external scrutiny because the research community functioned as an independent check that would surface environmental problems a brand might otherwise be exposed to unknowingly. When that access is obstructed, the external check weakens, and the practical effect is that an advertiser can no longer implicitly rely on the assumption that someone independent is monitoring the environment its ads run in. The burden of detecting and avoiding harmful adjacency therefore shifts back onto the advertiser's own first-party brand-safety tooling, inclusion and exclusion lists, and post-campaign placement audits. The defensible response is to assume less external transparency rather than more: move from periodic spot checks to continuous adjacency review for sensitive categories, prefer inclusion-led buying over broad reach when external visibility is constrained, and apply heightened controls during elections and high-risk news cycles when amplification dynamics are most volatile. It is also a reason to escalate, not relax, scrutiny of political and issue advertising during this period, because that is the category where reduced systemic-risk visibility and heightened transparency obligations intersect most sharply. The broader point is that platform transparency failures do not reduce an advertiser's responsibility for the environment it buys into — they increase it, because the external safety net the advertiser was implicitly relying on is thinner. Reassess these controls as remediation progresses by tracking the situation through the policy tracker and reviewing the systemic-risk framework in the EU DSA compliance overview.
What is the single most important action to take in response to this decision?
If only one change is made in response to the X decision, it should be to establish and maintain an independent system of record for every campaign run on the platform, because this single control mitigates the largest share of the inherited exposure the decision creates. The reason this is the highest-leverage action is that all three breach categories converge on the same advertiser vulnerability: a loss of reliable, authoritative documentation. The ad repository deficiency means the platform's own archive cannot be trusted as the record of what you ran. The deceptive verification finding means badge-based vetting leaves no defensible identity trail. The researcher-access obstruction means external parties can no longer independently document the environment your ads appeared in. An independent system of record directly addresses the first and partially addresses the second, and it is the foundation that every other control depends on. Concretely, this means retaining, for every X campaign, the full creative as run, the legal entity that paid, the precise targeting parameters, the flight dates, the internal approvals, and — for creator and partner relationships — the independent identity and ownership verification performed and the disclosure language used. This archive should be maintained on the advertiser's own infrastructure, not exported from or dependent on the platform repository, and it should be complete enough that the advertiser could reconstruct and defend any campaign without reference to X's systems at all. With that record in place, the remaining actions — re-baselining verification away from the badge, shifting to inclusion-led buying, increasing adjacency-audit cadence, and escalating political-ad documentation — become incremental refinements rather than gaps. Without it, every other control is undermined because there is no defensible evidence trail when a campaign is questioned. Operationalize this by pre-flighting every campaign through the AI compliance audit so that what enters the independent archive is already validated, and by monitoring remediation and enforcement developments through the policy tracker so the record-keeping posture is adjusted as the platform's obligations resolve.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Keyword Risk Checker first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#X Ads#DSA#Ad Compliance#Brand Safety#Disclosure Rules#EU Regulation#Ad Transparency#Content Moderation#Advertisers#Agencies#2026 Policy

Share This Report

TweetShare

Related Posts

Related Resources